Category: Insights

  • We Read Every SEC Enforcement Document Since 2010. Here Is What They Actually Charge.

    Lately I have been getting a lot of requests to demonstrate how a local AI program actually works. So I built the demonstration: a local AI lab, the kind I walked through in What It Actually Looks Like to Run a Local LLM at Your Firm, loaded with a dataset I can share freely because […]

  • Your Firm Is Already Using AI. Here’s How to Make It Defensible.

    Somewhere in your firm right now, an advisor is pasting text into an AI chatbot. Maybe it’s meeting notes. Maybe it’s a draft client letter. Maybe (and this is the one that should keep you up at night) it’s a spreadsheet with account numbers in column C. You can’t policy-memo your way out of this. […]

  • What It Actually Looks Like to Run a Local LLM at Your Firm

    Over the past year, a growing number of the advisers and fund managers we work with have asked the same question: “Can we run an AI model in-house, so client data never leaves the building?” The answer is yes, and the technology side is more approachable than most firms expect. One quiet desktop machine in […]

  • The Camera on Your Analyst’s Face: Why Smart Glasses Have No Place Near Client Data

    Camera-equipped glasses that look like ordinary Ray-Bans now sit at your workstations, recording screens, credentials, and conversations to a consumer cloud you do not control. Why it is a foreseeable risk under Reg S-P and Rule 206(4)-7 — and the one-paragraph prohibition that closes the gap.

  • Employees From Hell: What Disgruntled Insiders Actually Do, and How to Survive It

    The insider threat at a financial firm is not usually a spy. Six attack patterns from the adversary point of view — grounded in the CISA framework and mapped to the rules an examiner will hold you to.

  • Deploying Microsoft 365 as an SEC-Defensible Compliance Platform

    Most RIAs already own Microsoft 365. Far fewer have configured it to do the one thing the SEC now expects it to do: enforce, evidence, and retain the safeguards your written policies promise. The gap between “we have M365” and “we can demonstrate the safeguards rule to an examiner” is almost entirely a deployment problem […]

  • Deploying Google Workspace as an SEC-Defensible Compliance Platform

    Google Workspace is a capable compliance platform for an RIA — but only at the right edition, and only when the security controls that ship switched off are deliberately switched on. The single most expensive mistake advisers make here is assuming a Business-tier plan is enough. It is not: the controls the safeguards rule effectively […]

  • KerberRose Wealth Management Breach Post Mortem: One Inbox, 27,000 People

    One compromised employee mailbox at a wealth management firm reached a backup holding 27,076 clients’ Social Security and bank details. A breach teardown — and what amended Reg S-P now expects on identity, backup segmentation, and the 30-day notice clock.

  • The Attack That Doesn’t Need Your Password

    A subscription phishing kit (FBI Alert I-052126-PSA) hijacks Microsoft 365 OAuth tokens with no password and no MFA prompt. Why it is a Reg S-P and 206(4)-7 problem, and the Conditional Access change to make this week.

  • Is a Remote CISO for You?

    A five-sign self-assessment for RIA compliance officers — when a fractional Remote CISO closes the cybersecurity accountability gap the amended Reg S-P now assumes, at a fraction of a full-time hire.